As part of a new phasing campaign aimed at infiltrating corporate networks, employees, particularly at financial organisations, have been targeted using weaponised Excel documents.
ZD Net reports that the hacking campaign, dubbed MirrorBlast, was first discovered in September by cybersecurity firm ET Labs, leading to the attack being analysed by another cybersecurity company Morphisec, which has reported its findings in a blog post.
According to the post, malicious Excel files used in the hack are particularly dangerous due to the fact that they can bypass malware detection systems. The documents contain ‘extremely lightweight’ embedded macros, and attackers have switched from using newer VBA macros to legacy XLM macros in order to bypass anti-malware systems.
While the macros are disabled by default in the Microsoft Office suite of software, cybercriminals have been tricking users into enabling them with some very clever social engineering.
Morphisec believes that the Russia-based cybercriminal organisation TA505 is behind the spate of attacks due to similarities in the attacks chain, the GetandGo functional being used by the malware, the final payload, and the domain pattern.
TA505 has been active since at least 2014 and the group is known for frequently changing its malware to avoid detection.
However, the microcode used by MirrorBlast can only be executed on the 32-bit version of Microsoft Office due to a lack of compatibility with ActiveX objects.
The macro executes JavaScript code to see if a computer is running in administrator mode before launching msiexec.exe which is used to download and install an MSI package.
If you’re looking for managed IT services in Colchester, talk to us today.











